Trezor said its third-party email provider was breached, letting attackers send phishing emails from the company’s own domain. In an X post on Wednesday, Trezor told users that a message titled “Critical Security Alert: STM32 Entropy Vulnerability” did not come from the company and that they should not click any link in it.

Trezor said it has taken down the domain and is investigating how the attackers were able to send from its legitimate address. BitBox, the Swiss bitcoin hardware wallet maker, reported a similar campaign impersonating it the same day and told customers not to follow the instructions in the email. Marcello Paz, a crypto commentator who posts as MHPaz, shared screenshots of the message, which asked customers to update their devices because of a critical vulnerability said to affect newer hardware.


This story is an excerpt from the Unchained Daily newsletter.

Subscribe here to get these updates in your email for free


The emails carried official domain names and signatures. Trezor’s standing advice through the recent incidents has not changed: never enter a wallet backup on a website or share it with anyone.

The timing compounds an already bad month. Trezor disclosed on Aug. 13 that a breach at its shipping provider ShipMonk had exposed 13,689 customers, 11,742 of them with full contact details, on orders placed between May and August. Last week the company said another 67,000 U.S. customers were affected by the same breach, on orders going back to November 2019, with full names, shipping addresses, phone numbers and email addresses in the exposed records. Trezor has not published a combined figure, and the two disclosures could push the total above 80,000.

Customer data leaks at wallet makers have long tails. Trezor’s support ticketing portal was breached in January 2024, putting about 66,000 users at risk of phishing.

Related Listen: I Went Undercover to Interview a North Korean Crypto Hacker